Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Firefox extension missing from addons.mozilla.org #169

Open
shinenelson opened this issue Apr 10, 2021 · 9 comments
Open

Firefox extension missing from addons.mozilla.org #169

shinenelson opened this issue Apr 10, 2021 · 9 comments

Comments

@shinenelson
Copy link

I am surprised that no one has noticed this yet. The link to the Firefox add-on under Published versions in the readme leads to a 404 page. Searching for the keyword 'github hovercard' does not yield any results either.

Is that supposed to be how it is? Was the add-on intentionally removed from addons.mozilla.org?

@Justineo
Copy link
Owner

It has been taken it down by Mozilla and I was told they think there might be security vulnerabilities due to a core feature relies on directly outputting HTML from GitHub API (GitHub’s Markdown rendering API). Unfortunately I haven’t find time to deal with this yet.

@Justineo Justineo pinned this issue Apr 11, 2021
@shinenelson
Copy link
Author

If you still remember what the problem was, can you please put it up as an issue so that someone can take it up?

From what you have described, I think I know what you are talking about. I might be able to help fix the issue if it is not too grave.

@Justineo
Copy link
Owner

Hello,

Due to issues discovered during the review process, your add-on GitHub Hovercard has been disabled on addons.mozilla.org and no longer appears in the gallery. Users who have previously installed your add-on will be able to continue using it.

Please see the reviewer's comments below for more information.


Details:
This version didn't pass review because of the following problems:

  1. This add-on is creating DOM nodes from HTML strings containing potentially unsanitized data, by assigning to innerHTML, jQuery.html, or through similar means. Aside from being inefficient, this is a major security risk. For more information, see https://developer.mozilla.org/en-US/Add-ons/WebExtensions/Safely_inserting_external_content_into_a_page . Here are some examples that were discovered:

hovercard.js - line 2067

Please fix them and submit again.

@levifig
Copy link

levifig commented Apr 24, 2021

@Justineo Has it been removed from the Chrome Web Store for the same reason or have you taken it down? :o

@Justineo
Copy link
Owner

Google sent me a taken down notification yesterday claiming that I didn’t respond to their “previous” violation notification email which I didn’t receive. I contacted Google after that but haven’t received any response yet.

@Justineo
Copy link
Owner

Update: The Chrome extension is back online. Reviewers for Firefox Add-on haven't replied my inquiry yet.

@Pk13055
Copy link

Pk13055 commented Jun 2, 2021

Any updates regarding the firefox extension? I just got a new PC and realized I've been taking this extension for far too granted!

@MaxymVlasov
Copy link

Still not available in FF store

@lonix1
Copy link

lonix1 commented Sep 1, 2022

Still unavailable from the addons site. Can it be installed manually?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants